Show filters
39 Total Results
Displaying 1-10 of 39
Sort by:
Attacker Value
Unknown
CVE-2024-22477
Disclosure Date: July 09, 2024 (last updated August 20, 2024)
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.
0
Attacker Value
Unknown
CVE-2024-22377
Disclosure Date: July 09, 2024 (last updated August 20, 2024)
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
0
Attacker Value
Unknown
CVE-2023-40545
Disclosure Date: February 06, 2024 (last updated February 14, 2024)
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
0
Attacker Value
Unknown
CVE-2023-36496
Disclosure Date: February 01, 2024 (last updated February 10, 2024)
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.
0
Attacker Value
Unknown
CVE-2023-39930
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.
0
Attacker Value
Unknown
CVE-2023-39231
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.
0
Attacker Value
Unknown
CVE-2023-39219
Disclosure Date: October 25, 2023 (last updated February 02, 2024)
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
0
Attacker Value
Unknown
CVE-2023-37283
Disclosure Date: October 25, 2023 (last updated February 02, 2024)
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
0
Attacker Value
Unknown
CVE-2023-34085
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
0
Attacker Value
Unknown
CVE-2022-40725
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated.
0